Windows XP ToolBox
ID: ccdbfa9c-6e66-5c33-8e60-9e9871b022a4
STIX ID: report--ccdbfa9c-6e66-5c33-8e60-9e9871b022a4
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave with App‑Bound Encryption bypass via IElevator; Opera/Vivaldi via DPAPI; Firefox via NSS). It performs DLL injection into a headless Chromium process (Early Bird APC) to decrypt app_bound_encrypted_key, parses on‑disk SQLite/JSON stores, includes EDR‑evasion features, outputs structured JSON, and is intended for red‑team assumed‑breach testing but presents a realistic risk of credential theft and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
